Send to Syslog Server
  • 1 Minute To Read
  • Print
  • Share
  • Dark
    Light

Send to Syslog Server

  • Print
  • Share
  • Dark
    Light

The Send to Syslog Server action sends a message with the action results summary to syslog and optional messages with the device data for each of the devices in the query results.

The message includes the Enforcement Set name and the triggered query, the condition for executing the Enforcement action, if such exists, and number of current and previous results.

Message example:
Alert - "test" for the following query has been triggered: Missing Sophos

Alert Details
The alert was triggered because: The number of entities is above 0
The number of devices returned by the query:4
The previous number of devices was:4

You can view the query and its results here: https://demo-latest.axonius.com/devices?view=Missing Sophos



To use this action, you must enable the Use Syslog setting and configure Syslog host and port. For more details, see Global Settings.

To configure the Send to Syslog Server action, do as follows, from the Action Library, click Notify, and then click Send to Syslog Server.

Send to Syslog Server.png

Action Settings

  1. Send device data to syslog (required, default: False) - Select whether to send additional messages to syslog with the device data for each of the devices in the query results.
    • If enabled, in addition to the default Syslog message, Axonius will send the device data for each of the devices in the query results.
    • If disabled, Axonius will send to Syslog only the default message.
  2. Message severity (required, default: info) - Select the message severity: info, warning or error.



For more details on other Enforcement available actions, see Action Library.
For more details on Enforcement Set configurations, see Enforcement Set configuration.

Was This Article Helpful?